Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

1) They link the public key to your user account in their database.

2) Passkeys are 2FA by default. Someone needs to steal your phone where the private key is stored (first factor) and they would need your Face ID / Touch ID / PIN Code (second factor). Just loosing your phone doesn't give someone else the chance to use your passkey for authentication.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: